SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-8554

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address.

MEDIUM 5.0EPSS 9.27%

Does this matter?

Lower severity and a low EPSS score (9.27%). Track it; it rarely justifies an emergency change on its own.

Description

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

CVSS 3.1
5.0 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS
9.27% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-283
Affected
kubernetes/kubernetes · oracle/communications cloud native core network slice selection function · oracle/communications cloud native core policy · oracle/communications cloud native core service communication proxy
Source
jordan@liggitt.net

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.